CVE-2023-35944 is a medium-severity vulnerability affecting Envoy, an open-source edge and service proxy, specifically versions prior to 1.27.0, 1.26.4, 1.25.9, 1.24.10, and 1.23.12. It stems from inconsistent case-sensitivity in Envoy's internal scheme checks for HTTP/2, allowing mixed-case schemes like "htTp" or "htTps" to bypass or be rejected by the proxy. This can lead to information disclosure (I:L) with a CVSS score of 5.3. There is no known active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.23.0, < 1.23.12CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* | ||
>= 1.24.0, < 1.24.10CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* | ||
>= 1.25.0, < 1.25.9CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* | ||
>= 1.26.0, < 1.26.4CPE matchmatch criteria | cpe:2.3:a:envoyproxy:envoy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.